VYPR

Fauzantrif Election

by Fauzantrif Election Project

CVEs (2)

  • CVE-2020-9340HigFeb 22, 2020
    risk 0.47cvss 7.2epss 0.01

    fauzantrif eLection 2.0 has SQL Injection via the admin/ajax/op_kandidat.php id parameter.

  • CVE-2020-9336MedFeb 22, 2020
    risk 0.35cvss 5.4epss 0.01

    fauzantrif eLection 2.0 has XSS via the Admin Dashboard -> Settings -> Election -> "message if election is closed" field.